{"id":59,"date":"2026-06-05T22:29:19","date_gmt":"2026-06-05T22:29:19","guid":{"rendered":"https:\/\/inhochoi.com\/index.php\/2026\/06\/05\/eqst-insight-february-2025-financial-network-separation-reform-funksec-xwiki-rce\/"},"modified":"2026-06-06T23:27:19","modified_gmt":"2026-06-06T23:27:19","slug":"eqst-insight-february-2025-financial-network-separation-reform-funksec-xwiki-rce","status":"publish","type":"post","link":"https:\/\/inhochoi.com\/index.php\/2026\/06\/05\/eqst-insight-february-2025-financial-network-separation-reform-funksec-xwiki-rce\/","title":{"rendered":"EQST Insight February 2025: Financial Network Separation Reform, FunkSec &#038; XWiki RCE"},"content":{"rendered":"<p style=\"background:#f0f4ff;border-left:4px solid #0066cc;padding:12px 16px;margin-bottom:24px;\"><strong>&#128196; Original Report (PDF):<\/strong> <a href=\"https:\/\/assets.ctfassets.net\/6hqdqj4fjyeg\/gOC74fTnSLpzOiYbFtN8l\/17adffd70346b8e09e0e82b76bbaa054\/sk-shieldus-eqst-insight-february-2025-issue.pdf\" target=\"_blank\">Download EQST Insight 2025 February &rarr;<\/a><\/p>\n<p>EQST&#8217;s February 2025 report tackles Korea&#8217;s evolving financial sector network separation regulations, the rise of FunkSec as a data-auction-focused threat actor, and a remote code execution vulnerability in the XWiki enterprise wiki platform (CVE-2024-55879).<\/p>\n<h2>Headline: Network Separation Reform for Korea&#8217;s Financial Sector<\/h2>\n<p>Korea&#8217;s Financial Services Commission proposed a reform of the mandatory network separation requirements that have long governed how financial institutions must isolate their internal networks from the internet. The existing rules \u2014 designed in an era before cloud and SaaS were ubiquitous \u2014 have created significant operational friction without always improving security outcomes. The proposed reform moves toward a risk-based model: institutions can connect internal financial systems to the internet if they implement equivalent compensating controls (strong authentication, DLP, behavioural monitoring, etc.) and obtain regulatory approval. EQST analysts caution that relaxed network separation must be accompanied by significantly improved monitoring and detection capabilities, or it will increase rather than decrease risk.<\/p>\n<h2>Keep Up with Ransomware: FunkSec \u2014 Beyond RaaS to Data Auctions<\/h2>\n<p>FunkSec represents a departure from conventional ransomware operations. Rather than focusing on encryption-based extortion, FunkSec prioritises data theft and operates a dark web marketplace where stolen data is auctioned to the highest bidder. This model is dangerous for victims because payment of a traditional ransom does not resolve the data exposure threat \u2014 data may be sold to competitors, nation-state actors, or multiple buyers. EQST analysed FunkSec&#8217;s auction mechanics, noting that the group has developed a sophisticated reputation system to build buyer trust. Organisations should treat any ransomware incident as a potential data exfiltration event and prepare communications for regulators and affected parties regardless of whether a ransom is paid.<\/p>\n<h2>Research &#038; Technique: XWiki RCE \u2014 CVE-2024-55879<\/h2>\n<p>EQST disclosed CVE-2024-55879, a server-side template injection (SSTI) vulnerability in XWiki, the open-source enterprise wiki used extensively in corporate knowledge management and documentation. By inserting malicious XWiki syntax into a wiki page that is rendered server-side, an attacker with page-edit access can execute arbitrary code on the XWiki server. The vulnerability is particularly dangerous because wiki platforms are often granted broad internal access and may contain sensitive corporate information. XWiki released a patch and EQST recommends immediate upgrade, as well as reviewing which users have page-edit permissions.<\/p>\n<p><em>Source: SK Shieldus EQST Insight, February 2025 \u2014 <a href=\"https:\/\/www.skshieldus.com\/en\/report?tab=eqst\">skshieldus.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#128196; Original Report (PDF): Download EQST Insight 2025 February &rarr; EQST&#8217;s February 2025 report tackles Korea&#8217;s evolving financial sector network separation regulations, the rise of FunkSec as a data-auction-focused threat actor, and a remote code execution vulnerability in the XWiki enterprise wiki platform (CVE-2024-55879). Headline: Network Separation Reform for Korea&#8217;s Financial Sector Korea&#8217;s Financial Services [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":124,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-59","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/posts\/59","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/comments?post=59"}],"version-history":[{"count":1,"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/posts\/59\/revisions"}],"predecessor-version":[{"id":104,"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/posts\/59\/revisions\/104"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/media\/124"}],"wp:attachment":[{"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/media?parent=59"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/categories?post=59"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/inhochoi.com\/index.php\/wp-json\/wp\/v2\/tags?post=59"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}